Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users should upgrade to Silverstripe Framework 4.12.15 or above to address the issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-04-26T13:57:03.733Z
Updated: 2024-08-02T10:13:50.222Z
Reserved: 2023-01-06T14:21:05.890Z
Link: CVE-2023-22728
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-26T14:15:09.490
Modified: 2024-11-21T07:45:18.400
Link: CVE-2023-22728
Redhat
No data.